09-19-2019 06:40 AM
Hi,
is there any tcpdump like equivalent command for cisco. i want to see live packets on CLI.
09-19-2019 06:47 AM
Hi there,
There is EPC for most switches:
...and a similar function on the ASA firewalls.
Both allow you to read the contents of the buffer, but not do great analysis. For that you need to export the buffers to PCAP and feed into wireshark off-box.
There isn't anything like the monitor traffic interface command from Junos.
cheers,
Seb.
09-19-2019 11:21 AM
can you tell me from your experience that if it is CPU intensive
09-19-2019 12:34 PM
In my experience you are normally performing packet captures on fairly sizeable switches/ firewalls so the capture process has very little impact.
If the devices which you are looking at do not have the feature to save monitor sessions to internal buffers, you also have SPAN:
Keep in mind that will be caveats/ limitations depending on platform, but it is at least available on every cisco switching platform.
cheers,
Seb.
09-19-2019 05:00 PM
The problem is device is in Calgary and i am in Toronto and it doesn't support EPC.
09-19-2019 11:58 PM
….in which case ERSPAN is probably not available on your device either.
What is the device you are trying to capture on? Is the host traffic which is being captured routed on a device that supports EPC further upstream?
If not, then your best option is to have someone connect a laptop locally to the switch and configure a SPAN port which you can capture directly from.
cheers,
Seb.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide